Polycom HDX Series RCE

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

When doing external assessments you spend a decent amount of time footprinting your target and finding possible avenues of attack. Given a large corporate, you are pretty likely to hit video conferencing end-points. This post details a vulnerability in one of these video conferencing systems, the Polycom HDX series. I identified this vulnerability while still at [SensePost](https://sensepost.com/) and reported it to Polycom. The vulnerability was acknowledged and we were informed that a patch would be issued. This was over a year ago and I have yet to see an official [advisory or patch](http://support.polycom.com/content/support/security-center.html). They have fixed an XXS in the HDX series since the disclosure of this vuln, so maybe this has been deemed low impact. ### Polycom PSH The Polycom HDX Series exposes an administrative console on port 23. This administrative interface is built on PSH (Polycom Shell) and allows management of the underlying device. By default there is no...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息